Bill
Cyber Security Bill 2024
passed, as at 2024-11-29. Home Affairs portfolio.
- Sponsor
- Not recorded
- Portfolio
- Home Affairs
Recorded stages
- introduced — 2024-10-09
- second reading — 2024-10-09
- second reading — 2024-11-18
- other — 2024-11-19
- second reading — 2024-11-19
- second reading — 2024-11-19
- committee — 2024-11-19
- other — 2024-11-20
- third reading — 2024-11-20
- introduced — 2024-11-25
- second reading — 2024-11-25
- second reading — 2024-11-25
- second reading — 2024-11-25
- committee — 2024-11-25
- third reading — 2024-11-25
- passed — 2024-11-25
- royal assent — 2024-11-29
Divisions
No divisions recorded. Most questions are decided on the voices; this does not establish that a bill was unopposed.
Plain-language summary
Written by a model from the explanatory memorandum; not the record, as at 2024-10-09.
The Cyber Security Bill 2024 would create a legal framework to help the Australian Government respond to cyber security threats across the economy.
It would give the Minister power to set mandatory security standards for internet-connected smart devices, require entities to report ransomware payments, restrict how cyber incident information is shared, and set up a Cyber Incident Review Board.
The Bill defines smart devices as 'relevant connectable products', matching the United Kingdom's definition, and the Secretary of Home Affairs could issue compliance, stop or recall notices to enforce standards.
- Establishes the Minister's power to mandate security standards for smart devices.
- Introduces a mandatory reporting obligation for entities that receive a ransomware demand and choose to pay.
- Creates a 'limited use' obligation on how the National Cyber Security Coordinator can share cyber incident information.
- Sets up a Cyber Incident Review Board to review significant cyber incidents.
- Requires responsible entities to provide a statement of compliance for smart devices they supply.
- Gives the Secretary of Home Affairs power to issue enforcement notices for non-compliance.
Australian people and businesses, smart device manufacturers and suppliers, and entities affected by cyber incidents.
Sources
em
em supp
em supp
em revised
billhome
frl act